Drag or tap steps into the slots.
CS0-003 Practice Question: Arrange the steps for a typical digital forensics…
Arrange the steps for a typical digital forensics investigation process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Step 1: Identification, Step 2: Preservation, Step 3: Collection, Step 4: Examination, Step 5: Presentation
Digital forensics follows identification, preservation, collection, examination, and presentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Step 1: Identification, Step 2: Preservation, Step 3: Collection, Step 4: Examination, Step 5: Presentation
Why this is correct
This sequence matches the standard forensic workflow codified in guidance such as NIST SP 800-86: analysts first identify which systems, media, or artifacts may hold relevant evidence, then preserve that evidence in its original state (isolating the device, disabling remote wipe, hashing volatile data) before physically or logically collecting it via forensic imaging, examining the acquired image for artifacts, and finally presenting findings in a report or testimony that a court or management can act on.
- ✗
Step 1: Preservation, Step 2: Identification, Step 3: Collection, Step 4: Examination, Step 5: Presentation
Why it's wrong here
Placing preservation before identification is backward because an investigator cannot take steps to protect evidence integrity, such as write-blocking a drive or isolating a host from the network, until they first determine which specific systems or artifacts are actually in scope; preservation actions applied blindly before identification risk missing evidence sources entirely or wasting resources protecting irrelevant systems.
- ✗
Step 1: Identification, Step 2: Collection, Step 3: Preservation, Step 4: Examination, Step 5: Presentation
Why it's wrong here
Swapping collection ahead of preservation breaks chain of custody because collection involves actively acquiring data from live or powered systems, and doing so before preservation controls are in place, such as write-blockers or volatile-memory capture order, risks overwriting timestamps, triggering anti-forensic wiping, or losing RAM contents that must be captured first under the order of volatility principle.
- ✗
Step 1: Identification, Step 2: Preservation, Step 3: Examination, Step 4: Collection, Step 5: Presentation
Why it's wrong here
Running examination before collection is logically impossible in this five-step model because examination refers to the detailed technical analysis of an already-acquired forensic image or artifact set, such as parsing file system metadata or carving deleted files; there is nothing to examine until a forensically sound copy of the evidence has first been collected from the preserved source.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.